StackRadar

CVE-2023-46673

Medium

Advisory

Published 22 Nov 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.008
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
30
of 17,781 indexed, latest versions
Container images
29
deployed by those charts
Fix available
1 of 1
affected package

Elasticsearch Improper Handling of Exceptional Conditions

Carried by container images the latest versions of 30 of 17,781 indexed charts deploy, on 29 images.

Affected packageAffected versionsFixed inImages
elasticsearchmaven7.0.0, 7.4.2, 7.6.0, 7.8.1+17 more7.17.14, 8.10.329
OSV records
GHSA-285m-vhfq-xx4h
Also known as
BIT-elasticsearch-2023-46673

Charts affected

30 by stars
ChartLatestAffected imagesRadar Score
sonarqubesonarqubeVerified publisher10.0.0+5211 of 3See more

sonarqube sonarqube 10.0.0+521

1 of the 3 container images this version deploys carry CVE-2023-46673.

Container imageDigestPackageFixed in
library/sonarqube:10.0.0-communityef9723cf4fe4
elasticsearch@8.6.1
8.10.3

Open the chart page →

6,556
sonarqube-ltssonarqubeVerified publisher1.0.16+981 of 4See more

sonarqube-lts sonarqube 1.0.16+98

1 of the 4 container images this version deploys carry CVE-2023-46673.

Container imageDigestPackageFixed in
library/sonarqube:8.9.2-community88cd63154d4b
elasticsearch@7.12.1
7.17.14

Open the chart page →

4,099
sonarqube-dcesonarqubeVerified publisher0.1.2+1212 of 5See more

sonarqube-dce sonarqube 0.1.2+121

2 of the 5 container images this version deploys carry CVE-2023-46673.

Container imageDigestPackageFixed in
library/sonarqube:9.1.0-datacenter-search7e43ff493a47
elasticsearch@7.14.1
7.17.14
library/sonarqube:9.1.0-datacenter-appa9bc5a3a1fc3
elasticsearch@7.14.1
7.17.14

Open the chart page →

8,698
skywalkingkubesphere-testVerified publisher3.1.01 of 4See more

skywalking kubesphere-test 3.1.0

1 of the 4 container images this version deploys carry CVE-2023-46673.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:8.1.0-es7641237e0299b
elasticsearch@7.0.0
7.17.14

Open the chart page →

18,042
apache-rangerapache-ranger0.1.01 of 2See more

apache-ranger apache-ranger 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-46673.

Container imageDigestPackageFixed in
apache/ranger:2.7.076c176e8a0e4
elasticsearch@7.10.2
7.17.14

Open the chart page →

7,740
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2023-46673.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-elk:latest4228b7a8ef40
elasticsearch@7.11.1
7.17.14

Open the chart page →

17,896
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-46673.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
elasticsearch@7.10.2
7.17.14

Open the chart page →

10,730
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2023-46673.

Container imageDigestPackageFixed in
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
elasticsearch@7.17.1
7.17.14

Open the chart page →

38,346
zammaddevplayer0Verified publisher4.0.51 of 4See more

zammad devplayer0 4.0.5

1 of the 4 container images this version deploys carry CVE-2023-46673.

Container imageDigestPackageFixed in
zammad/zammad-docker-compose:zammad-elasticsearch-4.1.0-318274d75a51fc
elasticsearch@7.10.1
7.17.14

Open the chart page →

6,110
elasticinseefrlab2.2.01 of 2See more

elastic inseefrlab 2.2.0

1 of the 2 container images this version deploys carry CVE-2023-46673.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
elasticsearch@7.17.3
7.17.14

Open the chart page →

17,284
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2023-46673.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.0332c6d416808
elasticsearch@7.17.0
7.17.14

Open the chart page →

31,844
elasticsearchromanow-helm-chartsVerified publisher1.7.11 of 2See more

elasticsearch romanow-helm-charts 1.7.1

1 of the 2 container images this version deploys carry CVE-2023-46673.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.8fdc73b3249c1
elasticsearch@7.17.8
7.17.14

Open the chart page →

6,045
airbyte-cronairbyteVerified publisher0.40.371 of 1See more

airbyte-cron airbyte 0.40.37

1 of the 1 container images this version deploys carry CVE-2023-46673.

Container imageDigestPackageFixed in
airbyte/cron:0.40.17caf4f551c546
elasticsearch@7.16.3
7.17.14

Open the chart page →

1,413
opendistro-esbeeinventor1.15.11 of 3See more

opendistro-es beeinventor 1.15.1

1 of the 3 container images this version deploys carry CVE-2023-46673.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
elasticsearch@7.10.2
7.17.14

Open the chart page →

5,806
apache-ranger-admindata-platform-stableVerified publisher0.2.01 of 2See more

apache-ranger-admin data-platform-stable 0.2.0

1 of the 2 container images this version deploys carry CVE-2023-46673.

Container imageDigestPackageFixed in
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
elasticsearch@7.6.0
7.17.14

Open the chart page →

8,245
elasticsearch-umbrellaempathyco0.8.121 of 3See more

elasticsearch-umbrella empathyco 0.8.12

1 of the 3 container images this version deploys carry CVE-2023-46673.

Container imageDigestPackageFixed in
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
elasticsearch@7.17.2
7.17.14

Open the chart page →

10,564
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2023-46673.

Container imageDigestPackageFixed in
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
elasticsearch@7.15.1
7.17.14

Open the chart page →

34,754
tampkubebb5.6.01 of 2See more

tamp kubebb 5.6.0

1 of the 2 container images this version deploys carry CVE-2023-46673.

Container imageDigestPackageFixed in
kubebb/gateway-api:v5.6.04d062f20309c
elasticsearch@7.8.1
7.17.14

Open the chart page →

4,664
sonarqubekubesphereVerified publisher6.7.01 of 3See more

sonarqube kubesphere 6.7.0

1 of the 3 container images this version deploys carry CVE-2023-46673.

Container imageDigestPackageFixed in
library/sonarqube:8.9-communityeb2f0be32efd
elasticsearch@7.16.2
7.17.14

Open the chart page →

2,273
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2023-46673.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
elasticsearch@7.4.2
7.17.14

Open the chart page →

7,929
elasticsearch-chartmy-elasticsearch0.1.01 of 2See more

elasticsearch-chart my-elasticsearch 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-46673.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
elasticsearch@7.17.3
7.17.14

Open the chart page →

9,300
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-46673.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
elasticsearch@7.15.2
7.17.14

Open the chart page →

13,607
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-46673.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
elasticsearch@7.15.2
7.17.14

Open the chart page →

11,738
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-46673.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
elasticsearch@7.15.2
7.17.14

Open the chart page →

13,568
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-46673.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
elasticsearch@7.15.2
7.17.14

Open the chart page →

13,551
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-46673.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
elasticsearch@7.15.2
7.17.14

Open the chart page →

13,455
ussigw-coreopenshift1.0.41 of 1See more

ussigw-core openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-46673.

Container imageDigestPackageFixed in
gurolakman/ussigw-core:1.0.48739565c3ea2
elasticsearch@7.15.2
7.17.14

Open the chart page →

13,100
reportportalreportportal5.7.21 of 8See more

reportportal reportportal 5.7.2

1 of the 8 container images this version deploys carry CVE-2023-46673.

Container imageDigestPackageFixed in
reportportal/service-jobs:5.7.2dc166c58485a
elasticsearch@7.9.3
7.17.14

Open the chart page →

25,737
netforge-besvtechVerified publisher0.0.21 of 3See more

netforge-be svtech 0.0.2

1 of the 3 container images this version deploys carry CVE-2023-46673.

Container imageDigestPackageFixed in
conductoross/conductor:3.31.09fba127693e6
elasticsearch@7.17.11
7.17.14

Open the chart page →

4,674
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2023-46673.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
elasticsearch@7.10.2
7.17.14

Open the chart page →

5,806

Container images carrying it

29 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
elasticsearch@7.10.2
7.17.14
2
library/elasticsearch:7.17.35e6ac15bf6a5
elasticsearch@7.17.3
7.17.14
2
airbyte/cron:0.40.17caf4f551c546
elasticsearch@7.16.3
7.17.14
1
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
elasticsearch@7.4.2
7.17.14
1
apache/ranger:2.7.076c176e8a0e4
elasticsearch@7.10.2
7.17.14
1
apache/skywalking-oap-server:8.1.0-es7641237e0299b
elasticsearch@7.0.0
7.17.14
1
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
elasticsearch@7.10.2
7.17.14
1
assistiot/cybersecurity-monitoring_ir-elk:latest4228b7a8ef40
elasticsearch@7.11.1
7.17.14
1
conductoross/conductor:3.31.09fba127693e6
elasticsearch@7.17.11
7.17.14
1
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
elasticsearch@7.6.0
7.17.14
1
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
elasticsearch@7.17.2
7.17.14
1
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
elasticsearch@7.15.1
7.17.14
1
gurolakman/smsf-configuration:1.0.49abb3882bcbd
elasticsearch@7.15.2
7.17.14
1
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
elasticsearch@7.15.2
7.17.14
1
gurolakman/smsf-momt:1.0.4ce23b20a8a17
elasticsearch@7.15.2
7.17.14
1
gurolakman/smsf-registration:1.0.4b22e746edd5d
elasticsearch@7.15.2
7.17.14
1
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
elasticsearch@7.15.2
7.17.14
1
gurolakman/ussigw-core:1.0.48739565c3ea2
elasticsearch@7.15.2
7.17.14
1
kubebb/gateway-api:v5.6.04d062f20309c
elasticsearch@7.8.1
7.17.14
1
library/elasticsearch:7.17.0332c6d416808
elasticsearch@7.17.0
7.17.14
1
library/elasticsearch:7.17.8fdc73b3249c1
elasticsearch@7.17.8
7.17.14
1
library/sonarqube:9.1.0-datacenter-search7e43ff493a47
elasticsearch@7.14.1
7.17.14
1
library/sonarqube:8.9.2-community88cd63154d4b
elasticsearch@7.12.1
7.17.14
1
library/sonarqube:9.1.0-datacenter-appa9bc5a3a1fc3
elasticsearch@7.14.1
7.17.14
1
library/sonarqube:8.9-communityeb2f0be32efd
elasticsearch@7.16.2
7.17.14
1
library/sonarqube:10.0.0-communityef9723cf4fe4
elasticsearch@8.6.1
8.10.3
1
reportportal/service-jobs:5.7.2dc166c58485a
elasticsearch@7.9.3
7.17.14
1
zammad/zammad-docker-compose:zammad-elasticsearch-4.1.0-318274d75a51fc
elasticsearch@7.10.1
7.17.14
1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
elasticsearch@7.17.1
7.17.14
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.